logo

Linux Defense Evasion Techniques Detected by AhnLab EDR (1)

ID: a55ec25b-4f90-5761-8794-d1b0ed20cbd9

STIX ID: report--a55ec25b-4f90-5761-8794-d1b0ed20cbd9

Feed Name: ASEC

Threat Score
65/100

Date Published: 2024-06-14

Date Updated: 2026-04-26

Author: Sanseo

...
...

This report describes Linux defense-evasion techniques observed in the wild — including disabling host firewalls (iptables, UFW, firewalld), deactivating Linux Security Modules (AppArmor/SELinux), and deploying kernel/user-mode rootkits (Diamorphine, Reptile) — with examples such as the Kinsing coinminer and the Watchdog group; it explains how AhnLab EDR detects these behaviors and helps administrators respond.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.